5v0-3521 Exam QuestionsBrowse all questions from this exam

5v0-3521 Exam - Question 50


An administrator deployed vRealize Operations and has been tasked with ensuring that the VMware SDDC remains compliant to the VMware vSphere Security Configuration Guide. The compliance benchmark is showing that the VMware SDDC is not completely compliant to the standards.

Which three symptoms could have triggered a compliance alert? (Choose three.)

Show Answer
Correct Answer: ACF

The compliance alert could be triggered by several symptoms. One possible cause is that the lockdown mode on a vSphere ESXi host is set to Disabled, as lockdown mode is a security feature that restricts direct access and it's recommended to be enabled. Another potential cause is that the SNMP service on a vSphere ESXi host is set to Disabled, which can be against the security guidelines if SNMP monitoring is required to ensure proper management and compliance. Additionally, having the Forged Transmit policy set to allow on a Distributed Port Group could be insecure as it allows forged Ethernet frames to be sent, which can undermine network security. Hence, the combination of these three factors aligns with common security guidelines and why they would trigger a compliance alert.

Discussion

2 comments
Sign in to comment
koso77Options: ACF
Jul 21, 2023

I think its correct according the hardening document.

koso77
Jul 25, 2023

Correcting myself ABF

r3nt0nn
Jan 3, 2024

I think AEF is the correct.

cam4l3onOptions: AEF
Mar 8, 2024

AEF, checked in hardening guide: https://core.vmware.com/vmware-vsphere-7-security-configuration-guide